File name:

InstMsiW.exe

Full analysis: https://app.any.run/tasks/cb15572e-f387-4162-a482-ee53519bebc2
Verdict: Malicious activity
Analysis date: October 24, 2023, 06:29:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MS CAB-Installer self-extracting archive
MD5:

85F037EF77E3AA6FA47E86A2B37B2A13

SHA1:

D28633294F9DFE2AA4D423B7D19CFC476DDE6F18

SHA256:

E22ABF7C2F46BCB06BE5357B3EC557AD572066F54FB575E2929AEB22A4EC2268

SSDEEP:

49152:bRLrnUlCoAy0ooF/nOGft1bDnyBagO+FzqvqA9Zuws/jM/qjTLLIDyeOepOGeo4H:bFbUlCoH0o2nr73nLgOdC0PXqjD0yerY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • msiinst.exe (PID: 3800)
      • msiinst.exe (PID: 2748)
      • msiinst.exe (PID: 3412)
      • msiinst.exe (PID: 3220)
    • Drops the executable file immediately after the start

      • InstMsiW.exe (PID: 3880)
      • InstMsiW.exe (PID: 3404)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • InstMsiW.exe (PID: 3880)
      • InstMsiW.exe (PID: 3404)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
    • The process creates files with name similar to system file names

      • InstMsiW.exe (PID: 3880)
      • InstMsiW.exe (PID: 3404)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
  • INFO

    • Checks supported languages

      • InstMsiW.exe (PID: 3880)
      • msiinst.exe (PID: 3800)
      • InstMsiW.exe (PID: 3404)
      • msiinst.exe (PID: 2748)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
      • msiinst.exe (PID: 3412)
      • msiinst.exe (PID: 3220)
    • Manual execution by a user

      • InstMsiW.exe (PID: 2352)
      • InstMsiW.exe (PID: 3404)
      • InstMsiW.exe (PID: 2792)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
      • taskmgr.exe (PID: 3200)
    • Create files in a temporary directory

      • InstMsiW.exe (PID: 3880)
      • InstMsiW.exe (PID: 3404)
      • InstMsiW.exe (PID: 2076)
      • InstMsiW.exe (PID: 3756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1998:10:05 15:12:12+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, 32-bit, No debug
PEType: PE32
LinkerVersion: 5.12
CodeSize: 36864
InitializedDataSize: 1468416
UninitializedDataSize: -
EntryPoint: 0x273d
OSVersion: 5
ImageVersion: 5
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.20.1710.0
ProductVersionNumber: 11.20.1710.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Installer for the Windows Installer
FileVersion: 1.20.1710.0
InternalName: InstMsi.exe
LegalCopyright: Copyright (c) Microsoft Corp. 1999
OriginalFileName: Msi.dll,MsiHnd.dll,MsiExec.exe
ProductName: Windows Installer - Unicode
ProductVersion: 1.20.1710.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
12
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start instmsiw.exe msiinst.exe instmsiw.exe no specs instmsiw.exe msiinst.exe instmsiw.exe no specs instmsiw.exe msiinst.exe instmsiw.exe msiinst.exe taskmgr.exe no specs instmsiw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2076"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Installer for the Windows Installer
Exit code:
0
Version:
1.20.1710.0
Modules
Images
c:\users\admin\desktop\instmsiw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2352"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Installer for the Windows Installer
Exit code:
3221226540
Version:
1.20.1710.0
Modules
Images
c:\users\admin\desktop\instmsiw.exe
c:\windows\system32\ntdll.dll
2472"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Installer for the Windows Installer
Exit code:
3221226540
Version:
1.20.1710.0
Modules
Images
c:\users\admin\desktop\instmsiw.exe
c:\windows\system32\ntdll.dll
2748C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe /i instmsi.msi /qb+C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe
InstMsiW.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\msiinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2792"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Installer for the Windows Installer
Exit code:
3221226540
Version:
1.20.1710.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\instmsiw.exe
3200"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3220C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe /i instmsi.msi /qb+C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe
InstMsiW.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\msiinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
3404"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Installer for the Windows Installer
Exit code:
0
Version:
1.20.1710.0
Modules
Images
c:\users\admin\desktop\instmsiw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
3412C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe /i instmsi.msi /qb+C:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exe
InstMsiW.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\msiinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
3756"C:\Users\admin\Desktop\InstMsiW.exe" C:\Users\admin\Desktop\InstMsiW.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Installer for the Windows Installer
Exit code:
0
Version:
1.20.1710.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\instmsiw.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
177
Read events
171
Write events
2
Delete events
4

Modification events

(PID) Process:(3880) InstMsiW.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:wextract_cleanup0
Value:
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(3404) InstMsiW.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:wextract_cleanup0
Value:
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(2076) InstMsiW.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:wextract_cleanup0
Value:
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(3756) InstMsiW.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:wextract_cleanup0
Value:
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(3200) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:UsrColumnSettings
Value:
1C0C0000340400000000000050000000010000001D0C0000350400000000000023000000010000001E0C000036040000000000003C000000010000001F0C000039040000000000004E00000001000000200C000037040000000000004E00000001000000
(PID) Process:(3200) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
30030000E803000001000000010000004401000076000000DC0200005C0200000300000001000000000000000000000001000000000000000100000000000000000000000200000004000000090000001D000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009C00000040000000210000004600000052000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000002000000010000000300000004000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0500000000000000FFFFFFFF00000000020000000300000004000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000630060003C005A00FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000010000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0400000000000000FFFFFFFF00000000FFFFFFFF4F00000028000000500000003400000050000000000000000100000002000000030000000400000000000000FFFFFFFF43000000000000000000000001000000
Executable files
52
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiinst.exeexecutable
MD5:E02A5954D711F5F01F59B085D0178BE5
SHA256:8B9B4D64AE33D3AB2040C17CD1B89D96158CF74C90B434B9DBAAA60C243774C7
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\imagehlp.dllexecutable
MD5:8A6014F79FD552E1E3CA12F0377C359D
SHA256:95E9816B2948BFBBBDD1EC1A8016E650AA3E827A7B2AAC6B0EF415FCDD14719B
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msihnd.dllexecutable
MD5:6596B8E1EB71F3B2E2FA8CE17273344C
SHA256:9F3D7D3C75B871C1BA3330FD04F334B29CCF4D3B3E37B271D53BDE3CDF8F034C
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msiexec.exeexecutable
MD5:11C32AA2E3C927EBA0CFBF262490A0A3
SHA256:21E5A5FC130A7BCF7C1096D8A1F24459498ECC002D7D22CD12EBD3E57EC1FD9F
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msi.dllexecutable
MD5:37BDD7F291A35EB9856B6D1DE9D5B0B8
SHA256:0AE46E41350B8DAC953E1C29019FDEABEF1B564A3EAEA7A06E94751E0272727E
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msls31.dllexecutable
MD5:2CAB9989FB957EFD98DBBBCB9B1946AB
SHA256:841FDE9B24476A7ED364A3E4A1470AC9B7358BC92F29FCA4A06AAB557D140850
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\usp10.dllexecutable
MD5:771230886F61696FCC54EE0DC154C9D2
SHA256:9B229E275902C2DFAEC8AA69B17BA7BA73451099DE551F17721B73F98428E08E
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\riched20.dllexecutable
MD5:CDE130B22C3BC4B4AA8DF5F10D17AB82
SHA256:395D33B57775FDAEECF85B76F514DDE43569F38800FB4BA369647C4E288D88D2
3404InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\msimsg.dllexecutable
MD5:723F8FA06CD72F0BB3A24D4176430718
SHA256:81CE15DB7DE00E771AC01174AC43090C3D92F17730790686EC271B775F773C67
3880InstMsiW.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\instmsi.msiexecutable
MD5:91CBC8DA84235B677102CD9977B9659D
SHA256:47C05B3F50B94E04F4338C00DDD1BBC8DD8D1F0764BB268135F25C5CCA39A974
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
Process
Message
msiinst.exe
MSIINST: UNICODE BUILD
msiinst.exe
The Windows Installer can only be update by Service Packs on Microsoft Windows 2000.
msiinst.exe
MSIINST: !Win9X
msiinst.exe
MSIINST: !Win9X
msiinst.exe
The Windows Installer can only be update by Service Packs on Microsoft Windows 2000.
msiinst.exe
MSIINST: UNICODE BUILD
msiinst.exe
MSIINST: !Win9X
msiinst.exe
MSIINST: UNICODE BUILD
msiinst.exe
The Windows Installer can only be update by Service Packs on Microsoft Windows 2000.
msiinst.exe
MSIINST: UNICODE BUILD